It's nice when an online service promptly fixes security flaws. But sometimes the bugs themselves are “the eroticization of gender: a materialist analysis of patriarchy and gender identityâ€so egregious that you have to wonder what other dangers lurk in that code.
Case in point: video sharing app TikTok.
Security company Check Point Research found a number of security issues in the TikTok app and on its website, potentially allowing an attacker to control someone else's account, delete their videos, upload unauthorized videos, make private videos public and reveal a user's personal information, including their private email address.
TikTok being one of the most popular apps out there, this would be pretty bad. But, again, it's the amount and the type of bugs found that's more worrying.
One issue allowed bad actors to send an SMS message to any phone number in the name of TikTok. Basically, with some fairly simple code tweaking, an attacker could've sent an SMS of the type: "Please download this urgent update," with a link leading to a malicious app, and have the SMS actually arrivefrom TikTok. Ugh.
A different bug allowed an attacker to execute JavaScript code on behalf of the victim, and combining the two bugs allowed an attacker to perform actions on the victim's account without consent.
There were other bugs, and some required a fair amount of technical knowledge to exploit, but line them up and it feels like TikTok's security is, overall, more than a little sloppy.
"Before public disclosure, Check Point agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage further collaboration with security researchers," TikTok told BBC in a statement.
SEE ALSO: Samsung's new vertical 4K TV is perfect for...TikTok?The company said there's no indication that an attacker actually exploited any of these bugs prior to this disclosure.
TikTok made headlines last year when its owner, China's ByteDance, was fined by the FTC for illegally collecting children's data. The app was banned by the U.S. army due to cybersecurity concerns, and it's under investigation in the EU for how it handles children's data.
Topics Cybersecurity Social Media TikTok
The author of that heartbreaking dating profile for her husband has diedLaVar Ball: The basketball dad whose ego is big enough to overshadow March MadnessComedian shuts down racist audience member in the most beautiful wayBoaty McBoatface is on its first mission and we really wish it well'Hamilton' gets a second national tour because we deserve something niceFacebook just took a surprising stand on an important digital rights issueJ.K. Rowling predicted second Scottish independence referendum like, one minute after BrexitStudent artists create gorgeous wearable sculptures for dancers with disabilitiesThe colors of India's Holi festival snapped by iPhonesPolitician denies sending tweet, giant screen behind him shows the tweetUptime — Watch videos togetherAn intense cold snap turned this waterfront home into a striking ice castle'Ghost in the Shell' gets brutally dragged in its own viral campaignTexas legislator expertly trolls Republicans with bill that would fine men for masturbatingThe 10 best Disney villain songsYou might not know it, but this Kiwi city is a total street art wonderlandLaVar Ball: The basketball dad whose ego is big enough to overshadow March MadnessApocalypse came a little early for this guy in 'Horizon: Zero Dawn'Congressman who made racist tweet doubles down on CNNFans may have guessed J.K. Rowling's next book title How Much of Van Gogh’s Ear Did He Cut Off? Bess Wohl’s play ‘Small Mouth Sounds’ returns to the stage. The Rise of the Spoiler Alert Best Echo deal: Certified refurbished 4th gen Echo on sale for $49.99 at Amazon Best Garmin deal: Get the Garmin Instinct Solar for under $200 Nathaniel Mackey & Cathy Park Hong with NYC High The Radical Politics in Cloud The World of ‘Garfield’ Parodies Runs Deeper Than You’d Dreamed The World’s Largest Picnic Basket is in Peril Prison Lit: Jones Very’s Words from the Asylum #ReadEverywhere, Even in the Ring Kool Customer: Hunter S. Thompson Sells Cigs in Puerto Rico 'Heardle' today: Correct answer and song hints for August 11 The iPhone 12's 0.5 selfie trend is a nostalgic protest against Instagram perfection Another Year for the NBA: Triptych for the End of a Season Best online subscription plan deal: All Grammarly Premium Plans are currently 50% off Wordle today: The answer and hints for October 20 Women's health app Flo launches feature for partners Hed: 'Loki' Season 2 explainer: H.H. Holmes and The Chicago World's Fair I used the iPad Air for a week for work — can it replace your laptop?
1.3902s , 8263.6796875 kb
Copyright © 2025 Powered by 【“the eroticization of gender: a materialist analysis of patriarchy and gender identityâ€】,Prosperous Times Information Network